Vulnerability Description
Insecure permissions in the Web management portal on all IP cameras based on Hisilicon Hi3510 firmware allow authenticated attackers to receive a network's cleartext WiFi credentials via a specific HTTP request. This affects certain devices labeled as HI3510, HI3518, LOOSAFE, LEVCOECAM, Sywstoda, BESDER, WUSONGLUSAN, GADINAN, Unitoptek, ESCAM, etc.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hisilicon | Hi3510 Firmware | - |
| Hisilicon | Hi3510 | - |
Related Weaknesses (CWE)
References
- https://dojo.bullguard.com/dojo-by-bullguard/blog/cam-hi-risk/MitigationThird Party Advisory
- https://dojo.bullguard.com/dojo-by-bullguard/blog/cam-hi-risk/MitigationThird Party Advisory
FAQ
What is CVE-2019-10710?
CVE-2019-10710 is a vulnerability with a CVSS score of 8.8 (HIGH). Insecure permissions in the Web management portal on all IP cameras based on Hisilicon Hi3510 firmware allow authenticated attackers to receive a network's cleartext WiFi credentials via a specific HT...
How severe is CVE-2019-10710?
CVE-2019-10710 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10710?
Check the references section above for vendor advisories and patch information. Affected products include: Hisilicon Hi3510 Firmware, Hisilicon Hi3510.